Business Email Compromise: How a Two-Line Email Drains a Bank Account

Oct 6, 2026

0 Comments

Business Email Compromise: How a Two-Line Email Drains a Bank Account

A business email compromise attack does not need malware, a dangerous attachment, or a sophisticated exploit.

Sometimes, it takes two lines:

“Our banking information has changed. Please send today’s payment to the new account.”

Or:

“I’m in a meeting. Wire $48,000 to this account before 3 p.m. Keep this confidential.”

The message looks ordinary. The sender may appear familiar. The request may match a real invoice or business need.

Then the money is gone.

Business email compromise, or BEC, is one of the most financially damaging cybercrime categories affecting small and mid-size businesses. According to the FBI’s 2024 Internet Crime Report, BEC caused approximately $2.77 billion in reported losses in 2024.

That number reflects reported losses. Many businesses never report an incident because they are embarrassed, uncertain about what happened, or focused on recovery. The actual impact is likely higher.

WHAT BUSINESS EMAIL COMPROMISE LOOKS LIKE

BEC is financial fraud carried out through email or another trusted communication channel.

An attacker may:

  • Take over an employee’s mailbox.
  • Spoof a vendor’s email address.
  • Register a look-alike domain.
  • Impersonate an executive.
  • Use information gathered from public websites and social media.
  • Monitor an existing email conversation before intervening.

The goal is simple: persuade someone to move money, change payment details, or expose sensitive information.

Common examples include:

VENDOR INVOICE FRAUD

Your accounts-payable employee receives an email from a familiar supplier.

The invoice appears legitimate. The amount is normal. The timing makes sense.

The only difference is the bank account.

The attacker asks your employee to update the vendor’s payment instructions. If the employee trusts the email and does not verify the change independently, the next payment goes to the criminal.

Abstract illustration of a vendor invoice payment being redirected through a fraudulent email

CEO OR EXECUTIVE IMPERSONATION

An employee receives an urgent message that appears to come from the owner, CEO, or CFO.

The request may say:

  • “I need this wire processed immediately.”
  • “I cannot take a call right now.”
  • “This is confidential.”
  • “Do not include the normal approval group.”
  • “I will explain when I am out of the meeting.”

The attacker is exploiting authority and urgency. The employee is not necessarily careless. They are being pushed to bypass the normal process.

PAYROLL REDIRECTS

An attacker impersonates an employee and requests a change to direct-deposit information.

The request may target HR, payroll, or an outside payroll provider. If accepted, the employee’s next paycheck goes to an account controlled by the criminal.

The business may still be responsible for paying the employee again.

WHY SECURITY TOOLS OFTEN MISS BEC

Traditional security tools are designed to detect malicious technical behavior.

They look for:

  • Malware.
  • Suspicious attachments.
  • Dangerous links.
  • Known phishing websites.
  • Unusual login locations.
  • Malicious code.
  • Unauthorized access patterns.

BEC can avoid all of those signals.

A fraudulent message may contain no attachment and no link. It may use a normal email service. It may come from a compromised account that has already passed authentication. It may simply ask a legitimate employee to perform a legitimate business action in an unusual way.

That is why BEC cannot be solved with email filtering alone.

Email security still matters. MFA still matters. Endpoint protection still matters. But payment controls and human verification are equally important.

This is a business process problem as much as a technology problem.

BEC VERSUS RANSOMWARE: WHICH COSTS MORE?

Ransomware receives more attention because it can shut down operations, encrypt files, and create an obvious crisis.

BEC is often quieter.

Ransomware may cause costs through:

  • Downtime.
  • Data restoration.
  • Forensic investigation.
  • Legal and regulatory work.
  • Customer notification.
  • Lost productivity.
  • Extortion payments.

BEC removes money directly from an account. It may not trigger an alarm until someone reconciles the bank statement or a vendor asks why an invoice remains unpaid.

The FBI’s 2024 report recorded approximately $2.77 billion in BEC losses. Ransomware figures are harder to compare because reported ransomware losses often exclude major consequential costs such as downtime, lost revenue, and recovery work. The FBI also notes that cybercrime reporting does not capture every incident or every dollar.

The practical difference is this:

  • Ransomware disrupts your ability to operate.
  • BEC can reduce your cash balance before you realize an attack occurred.
  • Both can create serious financial and reputational damage.
  • Neither should be treated as only an IT issue.

THE DEFENSES THAT ACTUALLY WORK

The strongest BEC defenses combine technology, process, and training.

1. VERIFY PAYMENT CHANGES BY CALLBACK

Any request to change bank details should require an independent callback.

Do not use the phone number in the email. Do not reply to the same email thread. Do not click a link provided in the request.

Use a trusted number already stored in your vendor records or accounting system.

Ask the vendor to confirm:

  • The requested account change.
  • The effective date.
  • The bank and account information.
  • The name of the employee who submitted the request.

The FBI’s BEC guidance specifically recommends verifying payment changes through a known communication channel.

2. REQUIRE TWO PEOPLE FOR HIGH-RISK CHANGES

One person should not be able to create a vendor, change its banking information, and approve the payment.

Use dual control for:

  • New vendors.
  • Bank-account changes.
  • Payroll direct-deposit changes.
  • Large wires.
  • Out-of-cycle payments.
  • Payments involving new countries or unusual currencies.

The second approver should review the request independently, not simply approve the first person’s work.

3. USE MFA ON EMAIL, BANKING, AND PAYROLL SYSTEMS

Multi-factor authentication makes stolen passwords much less useful to attackers.

Enable strong MFA on:

  • Business email.
  • Accounting and ERP systems.
  • Online banking.
  • Payroll platforms.
  • Password managers.
  • Remote-access tools.
  • Administrator accounts.

MFA is not a complete BEC solution. It does not stop a spoofed vendor or a fake executive address. It does reduce the chance that an attacker can quietly take over your own mailbox.

Prefer phishing-resistant methods where available, such as hardware security keys or passkeys.

4. MONITOR MAILBOX RULES AND FORWARDING

Attackers who compromise a mailbox may create hidden rules that:

  • Forward messages to an outside account.
  • Move replies into a hidden folder.
  • Delete security alerts.
  • Watch for invoices, wire instructions, or payroll conversations.
  • Suppress messages from finance staff.

Mailbox-rule monitoring should be part of your ongoing security program.

Review forwarding rules after suspicious activity, employee departures, password resets, and high-risk account changes. Alert on new external forwarding rules and unusual sign-in activity.

5. CREATE A VENDOR CHANGE-OF-BANK PROTOCOL

Write the process down before an incident happens.

Your protocol should define:

  • Who can request a change.
  • Who can approve it.
  • Which trusted contact method must be used.
  • What records must be retained.
  • How long verification takes.
  • What happens when a request is urgent.
  • What happens if the vendor cannot be reached.

A good protocol makes the safe action easier than the rushed action.

6. TRAIN STAFF TO RECOGNIZE AUTHORITY AND URGENCY

Employees need more than generic phishing training.

Show them the specific patterns BEC uses:

  • A senior leader asks for secrecy.
  • A vendor suddenly changes bank details.
  • A request bypasses normal approval.
  • The sender refuses a callback.
  • The message arrives near payroll or month-end.
  • The language feels urgent, unusual, or slightly out of character.
  • The request comes from a look-alike domain.
  • The payment amount or destination does not match normal activity.

The standard should be clear:

Urgency does not override verification. Authority does not replace verification.

WHAT TO DO IN THE FIRST HOUR

If you suspect a fraudulent payment or account change, act immediately.

FIRST 15 MINUTES

  • Stop any pending payment if possible.
  • Contact your bank’s fraud department.
  • Ask whether the transaction can be recalled, held, or frozen.
  • Preserve the original email and full headers.
  • Do not delete the conversation.

WITHIN 30 MINUTES

  • Notify your internal incident lead, owner, CFO, or executive team.
  • Contact the legitimate vendor or employee using a trusted number.
  • Secure affected accounts.
  • Reset passwords from a clean device.
  • Revoke active sessions.
  • Remove unauthorized mailbox rules and forwarding.
  • Review recent sign-ins and account activity.

WITHIN THE FIRST HOUR

  • Determine whether other payments or accounts are affected.
  • Contact your payroll provider if employee banking information was changed.
  • Document the timeline, decisions, account numbers, and communications.
  • Report the incident through the FBI’s Internet Crime Complaint Center.
  • Consult legal counsel, your cyber insurance carrier, and appropriate law enforcement contacts.

Do not wait for certainty. Early reporting can improve the chance of stopping or recovering funds.

Clock, bank alert, phone, and laptop connected by verification lines during a suspected payment fraud response

WHERE MANAGED IT SERVICES FIT

BEC protection is not one product. It is a coordinated operating model.

A practical review should cover:

  • Email security and MFA.
  • Identity and access management.
  • Mailbox-rule monitoring.
  • Finance and payroll permissions.
  • Vendor onboarding and payment controls.
  • Incident response procedures.
  • Security awareness training.
  • Backup and recovery readiness.
  • Logging and alerting.
  • Executive and finance-team workflows.

Our security services focus on identifying risks, prioritizing practical controls, and validating that those controls work. A focused security assessment typically takes one to two weeks, according to our standard assessment process. Remediation may take days or several weeks depending on your systems, vendors, and approval workflows.

Our consulting services can also support a defined BEC-readiness project without requiring you to hire a permanent security team. We document the work and transfer knowledge to your internal staff instead of creating unnecessary dependency.

That is the role of managed IT services for small business and cybersecurity consulting: reduce avoidable risk, improve reliability, and give your team a clear process when pressure is high.

START WITH AN HONEST CONVERSATION

You do not need to wait for a fraudulent payment to review your exposure.

We can help you identify where a two-line email could bypass your current controls, what should be fixed first, and which improvements can wait. We will be direct about what we can handle, what your team can manage internally, and where another specialist may be a better fit.

Contact Five 9 LLC for a no-pressure conversation about small business IT support, email security, payment verification, and incident readiness.

Five 9 Assistant

Automated · not a live person